RHSA-2011:0266: Low: fence security, bug fix, and enhancement update

Published Feb 16, 2011
·
Updated

The fence package allows failed or unreachable nodes to be forcibly<br>restarted and removed from a cluster.<br>Insecure temporary file use flaws were found in fenceegenera, fenceapc,<br>and fenceapcsnmp. A local attacker could use these flaws to overwrite an<br>arbitrary file writable by the victim running those utilities via a<br>symbolic link attack. (CVE-2008-4192, CVE-2008-4579)<br>This update also fixes the following bugs:<br><li> fenceapcsnmp now waits for five seconds after fencing to properly get</li> status. (BZ#494587)<br><li> The fencedrac5 help output now shows the proper commands. (BZ#498870)</li> <li> fencescsitest.pl now verifies that sgpersist is in the path before</li> running. (BZ#500172)<br><li> fencedrac5 is now more consistent with other agents and uses modulename</li> instead of modulename. (BZ#500546)<br><li> fenceapc and fencewti no longer fail with a pexpect exception.</li> (BZ#501890, BZ#504589)<br><li> fencewti no longer issues a traceback when an option is missing.</li> (BZ#508258)<br><li> fencesanbox2 is now able to properly obtain the status after fencing.</li> (BZ#510279)<br><li> Fencing no longer fails if fencewti is used without telnet. (BZ#510335)</li> <li> fencescsi getscsidevices no longer hangs with various devices.</li> (BZ#545193)<br><li> fenceilo no longer fails to reboot with ilo2 firmware 1.70. (BZ#545682)</li> <li> Fixed an issue with fenceilo not rebooting in some implementations.</li> (BZ#576036)<br><li> fenceilo no longer throws exceptions if the user does not have power</li> privileges. (BZ#576178)<br>As well, this update adds the following enhancements:<br><li> Support has been added for SSH-enabled RSA II fence devices. (BZ#476161)</li> <li> The APC fence agent will now work with a non-root account. (BZ#491643)</li> All fence users are advised to upgrade to this updated package, which<br>corrects these issues and adds these enhancements.<br>

Affected Software

0 affected components

Remediation

Event History

Mar 20, 2024
Advisory Published
via Red Hat·12:34 PM
Data Sourced
via Red Hat·12:34 PM
RemedyDescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2011:0266?

The severity of RHSA-2011:0266 is classified as moderate.

2

How do I fix RHSA-2011:0266?

To fix RHSA-2011:0266, update the affected fence package to the latest version provided by Red Hat.

3

What types of flaws are addressed in RHSA-2011:0266?

RHSA-2011:0266 addresses insecure temporary file use flaws in several fencing agents.

4

Who is affected by RHSA-2011:0266?

Local attackers on systems utilizing the affected fence package are at risk from RHSA-2011:0266.

5

What impact does RHSA-2011:0266 have on system security?

The impact of RHSA-2011:0266 is that it allows local attackers to potentially overwrite arbitrary files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203